Skip to content
SavaSync
← All legal documents

Data Processing Addendum

Effective 2026-09-01 · v1.4

Effective: September 1, 2026

This Data Processing Addendum ("DPA") is published by Tricky Labs LLC, a New Hampshire limited liability company doing business as SavaSync ("SavaSync," "we," "us," "our"), and forms part of our Terms of Service for every Studio and Instructor account (each, a "Studio").

1. Roles

When a Studio uses SavaSync to run its business, the Studio collects and controls personal data about its own clients — booking records, contact details, waiver signatures, intake-form responses (which may include health-related information the Studio chooses to ask about), and private client notes ("Studio Client Data").

A Studio that turns on the time clock also records personal data about its own staff: the hours they work, the activity each entry is for, and the full history of any change made to an entry, including who made it and when ("Studio Staff Data"). The Studio decides whether to keep these records at all — the time clock is off until a Studio switches it on — and decides what to do with them afterwards.

For Studio Client Data and Studio Staff Data, the Studio is the controller (it decides what to collect and why) and SavaSync is the processor (we store and process it only to provide the Platform). For data SavaSync collects for its own purposes — account registration, platform security, billing, aggregate analytics — SavaSync is an independent controller, as described in our Privacy Policy.

2. Scope and instructions

SavaSync processes Studio Client Data only:

  • to provide, maintain, and secure the Platform's features (bookings, payments, waivers, intake forms, notes, communications, recorded working hours) per the Terms of Service;
  • per the Studio's documented instructions expressed through its use of Platform features (for example, sending an email campaign the Studio composed); and
  • as required by law, in which case we will notify the Studio unless the law forbids it.

SavaSync does not sell Studio Client Data or Studio Staff Data, use either for advertising, or use either to train models.

SavaSync records working hours; it does not calculate wages, overtime, premiums or deductions, and it does not determine whether a Studio is complying with any law. A staff member can always read their own hours and the full history of changes to them, including changes a Studio made.

3. Confidentiality and security

  • Personnel with access to Studio Client Data are bound by written confidentiality obligations.
  • Data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Access is role-restricted and administrative access is logged.
  • Intake signature images are stored in private storage. Where the response was classified sensitive at the moment it was given, both the answers and the signature are readable only by the client who submitted them and by the owner of the account that took the booking — not by the Studio's other staff. See Section 5.

If SavaSync becomes aware of a personal-data breach affecting Studio Client Data, we will notify the affected Studio without undue delay and provide the information the Studio reasonably needs to meet its own notification obligations.

4. Sub-processors

The Studio authorizes SavaSync's use of these sub-processors for Studio Client Data:

Sub-processorPurpose
SupabaseDatabase, authentication, file storage
StripePayment processing, payouts, disputes
ResendEmail delivery (transactional + Studio campaigns)
TwilioSMS reminders (where enabled)
ExpoMobile push notifications
SentryError tracking, performance monitoring, diagnostic logs, and error-triggered session replay (masked by default; reports may include technical identifiers)
Google AnalyticsAggregate measurement of the savasync.com marketing site only — never the dashboard; IP truncated by Google, no account data sent, Google Signals off, no advertising account linked, 14-month retention
Google Maps PlatformGeocoding/timezone for Studio business addresses (no client data)
Zoom Video Communications, Inc.Creating class meeting links, for Studios that connect a Zoom account (Zoom account identifier and email, OAuth tokens, and the Class title — the meeting is a permanent recurring one with no scheduled time, so no Class dates or times are sent; no client data, and nothing at all is sent for Studios that never connect Zoom)
CloudflareHosting, CDN, TLS, cookieless aggregate site analytics

We will update this list when we add or replace a sub-processor that materially changes the processing of Studio Client Data, with notice via the mechanisms in the Terms of Service; a Studio that objects may close its account before the change takes effect.

5. Assistance and data-subject requests

If a Studio's client exercises a privacy right (access, correction, deletion, portability) directly with the Studio, these are the tools built into the Platform:

  • Export the Studio's client data. In Account settings → Studio data export, a Studio owner or admin can export the Studio Client Data the Studio controls — client roster and contact details, bookings and appointments, memberships and class packs, waiver signatures, tags, visits and private client notes — as a machine-readable archive containing an export.json file, a spreadsheet (CSV) rendering of the same records, and a plain-language README.txt that lists anything left out and the reason for it. The archive is produced on request and delivered over a private download link that expires after five minutes. One export per day.
  • A client can export their own record themselves. In Account settings → Your data, any account holder can download a copy of everything SavaSync holds about them, in the same format, without asking the Studio or us. That export includes the private client notes a Studio has written about them: a note about a person is information relating to that person. It does not identify which member of Studio staff wrote it.
  • Correction and deletion. A Studio can correct a client's record in the app. A client can correct their own profile from their account settings, and can delete their SavaSync account themselves, which starts the retention schedule in Section 6.

Two limits are deliberate and worth stating plainly. Intake-form responses (which may include health information) are not included in the Studio's bulk export: those answers are technically restricted to the person who gave them and the account owner, and a bulk copy would sit outside that restriction and outside the consent given for it — a Studio that needs them for its own controller obligation should contact us. And live credentials (payment-processor identifiers, push and invitation tokens, connected-app access tokens) are never written into any export.

These tools are a convenience, not the only route: anyone may still email legal@savasync.com to exercise any right, and we will provide reasonable assistance on request for anything the tools do not cover. We keep a register of the data-subject requests we receive, with a response clock on each one: our published default is a response within 30 days, extending only where a state mandates a longer window (see our Privacy Policy Section 5), and the register's deadline column carries the outer bound of 45 days as a backstop rather than as the promise. The exports and deletions run through the tools above are logged in that same register. If a client contacts SavaSync directly about data controlled by a Studio, we will refer the request to the Studio unless the law requires us to act ourselves.

6. Deletion and return

When a Studio closes its account, Studio Client Data follows the retention schedule in our Privacy Policy Section 7: a 30-day recovery window, then automated permanent deletion, except records we must retain (waiver signatures, payment and tax records, legal holds). While the account is still open, a Studio can produce this export itself at any time using the Studio data export described in Section 5. Closing an account disables sign-in for the recovery period, so from that point on the route is email: a Studio may request an export of its Studio Client Data in a machine-readable format via legal@savasync.com at any time before permanent deletion. Any archive a Studio produced with the self-service tool is deleted when the account is closed, so take the copy before you close it.

7. International transfers

SavaSync processes data in the United States, as described in Privacy Policy Section 9. Where cross-border data-transfer safeguards are required by law applicable to a Studio, contact us at legal@savasync.com.

8. Questions

Email legal@savasync.com.